Official Legal Policy

Around - Privacy Policy

Last Updated: September 22, 2026 • Effective Date: September 22, 2026

Table of Contents

  1. Data Controller & Grievance Officer Contact Information
  2. Age Requirement & Children's Privacy (COPPA & DPDP Act)
  3. Personal Data We Collect
  4. Legal Bases for Processing (GDPR & DPDP Act)
  5. Data Storage, Security & Encryption
  6. Third-Party Service Providers & Processors
  7. Data Retention & Deletion Schedule
  8. Your Data Protection Rights
  9. How to Request Account & Data Deletion
  10. International Data Transfers
  11. Changes to this Privacy Policy
  12. Contact Us

1. Data Controller & Grievance Officer Contact Information

Welcome to Around ("we", "our", or "us"). Around is a community awareness platform that enables users to discover, report, and discuss local events and incidents occurring in their vicinity.

For any questions, requests to exercise your statutory rights, or grievances regarding your personal data, you may contact our designated Grievance / Privacy Officer:

Response Timeline: In accordance with statutory obligations under GDPR and India's DPDP Act, we acknowledge and address all verified privacy queries and grievance redressal requests within thirty (30) days (or within the statutory timeframe mandated by applicable local law).

2. Age Requirement & Children's Privacy (COPPA & DPDP Act)

Around is strictly intended for individuals aged thirteen (13) years or older.

3. Personal Data We Collect

We collect data that you directly provide, information generated during your use of the application, and diagnostic metadata:

A. Information You Provide Directly

B. Information Collected Automatically

4. Legal Bases for Processing (GDPR & DPDP Act)

We process personal data only under recognized legal bases:

5. Data Storage, Security & Encryption

We maintain rigorous administrative, technical, and physical safeguards:

6. Third-Party Service Providers & Processors

We share personal data only with vetted service providers bound by confidentiality and data protection obligations:

Service Provider Role / Purpose Data Shared Security & Compliance Safeguards
Supabase Managed Authentication & PostgreSQL Database Account identifiers, email, hashed credentials, profile data SOC 2 Type II, ISO/IEC 27001:2022 certified; AES-256 encryption at rest
Cloudflare R2 Cloud Object Storage Uploaded photos, videos, and voice recordings SOC 2 Type II, ISO 27001 certified; AES-256 encrypted storage, presigned URLs
Resend Transactional Email Delivery Recipient email address, verification OTP codes SOC 2 Type II compliant; EU-U.S. Data Privacy Framework certified; TLS encryption
Expo (60 East Technologies) Push Notification Delivery Push notification tokens, notification snippets Standard Apple APNs and Google FCM delivery pipelines
Google Maps Platform Map Tiles & Geocoding Viewport coordinates, map tile requests Industry-standard cloud security and HTTPS transport
ip-api.com & api.ipify.org Fallback Coarse Geolocation Public IP address (during non-GPS map centering) Ephemeral processing, no persistent user tracking

We do not sell, rent, trade, or monetize your personal data to advertisers or third-party data brokers.

7. Data Retention & Deletion Schedule

8. Your Data Protection Rights

Under applicable regulations (including GDPR and India's DPDP Act), you possess the following statutory rights:

  1. Right of Access / Information: Confirm whether your data is being processed and request an electronic copy.
  2. Right to Correction / Rectification: Update or correct inaccurate personal data directly in the app.
  3. Right to Erasure ("Right to be Forgotten"): Request complete and permanent deletion of your account and data.
  4. Right to Withdraw Consent: Revoke permissions (camera, microphone, location, push notifications) at any time via your device settings.
  5. Right of Grievance Redressal (DPDP Act): Register a grievance with our Grievance Officer regarding any act or omission concerning your personal data.
  6. Right to Nominate (DPDP Act): Nominate an individual to exercise your data rights in the event of death or incapacity.

To exercise any of these rights, use the in-app controls or email our Grievance Officer at [INSERT MONITORED PRIVACY EMAIL].

9. How to Request Account & Data Deletion

In accordance with Apple App Store Guideline 5.1.1(v) and Google Play Data Safety requirements, users can permanently delete their account and all personal data at any time:

Method 1: In-App Self-Service Deletion (Immediate)

  1. Open the Around app.
  2. Navigate to Profile (bottom tab) → tap Settings (gear icon in header).
  3. Scroll down to the Account Actions section.
  4. Tap Delete Account.
  5. Review the confirmation dialog and tap Delete Permanently.
  6. Your account is immediately deactivated, active authentication sessions are revoked, and our backend triggers an automated purge of your database records and uploaded media from Cloudflare R2.

Method 2: Email Deletion Request

If you cannot access the app, email [INSERT MONITORED PRIVACY EMAIL] or aroundapp.feedback@gmail.com from the email address registered with your account, with the subject line "Account Deletion Request". We will process your request and confirm complete deletion within thirty (30) days.

10. International Data Transfers

If you access Around from outside the region where our primary servers operate, your data may be transferred across international borders to our secure cloud hosting infrastructure (including Supabase and Cloudflare). We ensure appropriate data protection agreements and technical safeguards are maintained to protect your data across borders.

11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When changes occur:

12. Contact Us

For any privacy-related questions, data requests, or complaints, please reach out to: