1. Data Controller & Grievance Officer Contact Information
Welcome to Around ("we", "our", or "us"). Around is a community awareness platform that enables users to discover, report, and discuss local events and incidents occurring in their vicinity.
For any questions, requests to exercise your statutory rights, or grievances regarding your personal data, you may contact our designated Grievance / Privacy Officer:
- Data Controller: Around Application Team
- Grievance / Privacy Officer: [INSERT GRIEVANCE OFFICER NAME / TITLE]
- Official Privacy & Grievance Email: [INSERT MONITORED PRIVACY EMAIL, e.g., privacy@aroundapp.com]
- General Support & Feedback Email: aroundapp.feedback@gmail.com
- Registered Address: [INSERT REGISTERED ADDRESS / CITY, COUNTRY]
Response Timeline: In accordance with statutory obligations under GDPR and India's DPDP Act, we acknowledge and address all verified privacy queries and grievance redressal requests within thirty (30) days (or within the statutory timeframe mandated by applicable local law).
2. Age Requirement & Children's Privacy (COPPA & DPDP Act)
Around is strictly intended for individuals aged thirteen (13) years or older.
- We do not knowingly collect, process, or solicit personal data from children under the age of 13.
- During registration, all users must input their Date of Birth. Our backend systems enforce an automated database check; accounts for users under 13 cannot be registered.
- If we learn that personal data of an individual under 13 has been collected without verified parental consent, we will immediately delete that information and terminate the account. If you believe a minor under 13 has registered, please contact our Grievance Officer immediately.
3. Personal Data We Collect
We collect data that you directly provide, information generated during your use of the application, and diagnostic metadata:
A. Information You Provide Directly
- Account Registration Data:
- Email Address (mandatory): Used for account credentials, verification via one-time passwords (OTP), and essential service notices.
- Username (mandatory): Public identifier displayed alongside incident reports, comments, and messages.
- Date of Birth (mandatory): Used strictly to enforce age compliance (13+) under applicable child data protection laws.
- Password: Stored using cryptographic bcrypt hashes; plaintext passwords are never stored or accessible by us.
- Phone Number (optional): If provided, used as an alternative identifier for sign-in.
- Profile Data: Avatar image, bio, and account privacy preferences (public vs. private profile).
- User-Generated Content & Media: Incident and event reports (titles, descriptions, categories, timestamps), uploaded photos, videos, and audio voice recordings recorded via microphone in community chats.
- Interactions & Messages: Direct and group chat messages (encrypted at rest using AES-256-GCM), incident/comment likes, event RSVPs, and follow relationships.
- Moderation Reports & Feedback: Reports filed concerning inappropriate content, abuse, harassment, or platform issues.
B. Information Collected Automatically
- Location Data:
- Precise GPS Location: When you grant foreground location permissions, we collect your coordinates (latitude/longitude) to show incidents near you on the interactive map and tag posts you create. Foreground location is accessed only while actively using the app. We do not track location in the background when the app is closed.
- Coarse (City-Level) IP Geolocation: If location permissions are denied, our backend estimates approximate city-level coordinates from your IP address via external geolocation utilities (
ip-api.com / api.ipify.org) to center the map feed.
- Device & Push Notification Tokens: Push tokens generated via the Expo Push Notification Service to deliver alerts for messages, comments, and incident updates. Device platform (iOS, Android, Web) is stored.
- Local Storage Tokens: Authentication session tokens cached securely on your device using encrypted native storage (
expo-secure-store).
- Crash & Diagnostic Logs: When an unhandled client error occurs, diagnostic data is transmitted to our self-hosted logging service (
POST /errors/client). This includes device OS, app version, route/screen name, timestamp, sanitized error messages, and stack traces. Credentials and private messages are scrubbed. Logs are automatically deleted after thirty (30) days.
4. Legal Bases for Processing (GDPR & DPDP Act)
We process personal data only under recognized legal bases:
- Performance of Contract: Delivering core platform features, displaying nearby incidents, managing user profiles, and facilitating user messaging.
- Consent: Accessing device hardware (precise GPS location, camera, photo library, microphone for voice notes) and delivering push notifications. You may revoke consent at any time in device settings.
- Legitimate Interests: Protecting platform security, combating spam, moderating abusive content, and resolving technical crashes.
- Legal Compliance: Enforcing minimum age verification (13+) and fulfilling valid statutory or law enforcement requests.
5. Data Storage, Security & Encryption
We maintain rigorous administrative, technical, and physical safeguards:
- Message Encryption at Rest: All private and group chat message contents are encrypted at rest using symmetric AES-256-GCM (Galois/Counter Mode) encryption with unique initialization vectors (IV) and authentication tags. Plaintext message bodies are not readable directly in database tables.
- Data in Transit: All communications between the mobile application, backend API, and database use modern Transport Layer Security (TLS 1.2 / TLS 1.3 / HTTPS).
- Password & Credential Security: Passwords and one-time verification codes (OTPs) are stored using cryptographic bcrypt hashes. OTPs expire within ten (10) minutes.
- Access Controls & Rate Limiting: Database tables are protected by strict row-level security (RLS), parameterized queries to prevent SQL injection, and rate limiting to prevent brute-force attacks.
6. Third-Party Service Providers & Processors
We share personal data only with vetted service providers bound by confidentiality and data protection obligations:
| Service Provider |
Role / Purpose |
Data Shared |
Security & Compliance Safeguards |
| Supabase |
Managed Authentication & PostgreSQL Database |
Account identifiers, email, hashed credentials, profile data |
SOC 2 Type II, ISO/IEC 27001:2022 certified; AES-256 encryption at rest |
| Cloudflare R2 |
Cloud Object Storage |
Uploaded photos, videos, and voice recordings |
SOC 2 Type II, ISO 27001 certified; AES-256 encrypted storage, presigned URLs |
| Resend |
Transactional Email Delivery |
Recipient email address, verification OTP codes |
SOC 2 Type II compliant; EU-U.S. Data Privacy Framework certified; TLS encryption |
| Expo (60 East Technologies) |
Push Notification Delivery |
Push notification tokens, notification snippets |
Standard Apple APNs and Google FCM delivery pipelines |
| Google Maps Platform |
Map Tiles & Geocoding |
Viewport coordinates, map tile requests |
Industry-standard cloud security and HTTPS transport |
| ip-api.com & api.ipify.org |
Fallback Coarse Geolocation |
Public IP address (during non-GPS map centering) |
Ephemeral processing, no persistent user tracking |
We do not sell, rent, trade, or monetize your personal data to advertisers or third-party data brokers.
7. Data Retention & Deletion Schedule
- Account Profile & Identity: Retained for the active lifetime of your account.
- Incident Reports & Posts: Retained until deleted by the author or removed via moderation.
- Chat Messages: Retained until deleted by participants or when the account is deleted.
- Verification OTPs: Expire after ten (10) minutes; expired codes are periodically purged.
- Crash & Diagnostic Logs: Retained in our
error_logs database table for a maximum of thirty (30) days, after which they are permanently deleted by automated daily cleanup jobs.
- Account Deletion Purge: When you request account deletion, all personal data—including profile records, posts, comments, likes, chat messages, push tokens, and Cloudflare R2 media files—are permanently and irreversibly purged from our database and storage buckets.
8. Your Data Protection Rights
Under applicable regulations (including GDPR and India's DPDP Act), you possess the following statutory rights:
- Right of Access / Information: Confirm whether your data is being processed and request an electronic copy.
- Right to Correction / Rectification: Update or correct inaccurate personal data directly in the app.
- Right to Erasure ("Right to be Forgotten"): Request complete and permanent deletion of your account and data.
- Right to Withdraw Consent: Revoke permissions (camera, microphone, location, push notifications) at any time via your device settings.
- Right of Grievance Redressal (DPDP Act): Register a grievance with our Grievance Officer regarding any act or omission concerning your personal data.
- Right to Nominate (DPDP Act): Nominate an individual to exercise your data rights in the event of death or incapacity.
To exercise any of these rights, use the in-app controls or email our Grievance Officer at [INSERT MONITORED PRIVACY EMAIL].
9. How to Request Account & Data Deletion
In accordance with Apple App Store Guideline 5.1.1(v) and Google Play Data Safety requirements, users can permanently delete their account and all personal data at any time:
Method 1: In-App Self-Service Deletion (Immediate)
- Open the Around app.
- Navigate to Profile (bottom tab) → tap Settings (gear icon in header).
- Scroll down to the Account Actions section.
- Tap Delete Account.
- Review the confirmation dialog and tap Delete Permanently.
- Your account is immediately deactivated, active authentication sessions are revoked, and our backend triggers an automated purge of your database records and uploaded media from Cloudflare R2.
Method 2: Email Deletion Request
If you cannot access the app, email [INSERT MONITORED PRIVACY EMAIL] or aroundapp.feedback@gmail.com from the email address registered with your account, with the subject line "Account Deletion Request". We will process your request and confirm complete deletion within thirty (30) days.
10. International Data Transfers
If you access Around from outside the region where our primary servers operate, your data may be transferred across international borders to our secure cloud hosting infrastructure (including Supabase and Cloudflare). We ensure appropriate data protection agreements and technical safeguards are maintained to protect your data across borders.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When changes occur:
- The "Last Updated" date at the top of this policy will be refreshed.
- For material modifications, we will provide conspicuous notice via an in-app banner or notification.
- Continued use of Around after the effective date of an updated policy signifies your acknowledgment of the revised terms.
12. Contact Us
For any privacy-related questions, data requests, or complaints, please reach out to: