Privacy Policy
Diamond Abstract Project
GDPR
🕐 Last updated: July 2026
At Diamond Abstract Project, we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal information when you use the Where We Go application. This policy complies with the General Data Protection Regulation (GDPR) and applicable Spanish data protection law.
👤
1. Information We Collect
We collect the following types of information when you use Where We Go: • Account Information: name, email address, profile photo • Authentication Data: login credentials via email, Google, or Apple • Location Data: GPS coordinates to show nearby events (only when permitted) • Payment Information: processed securely by Stripe (we do not store card data) • Booking History: events booked, tickets purchased • Device Information: device type, OS version, app version • Usage Data: interactions within the App for analytics purposes • Communications: messages sent via in-app chat
🧠
2. How We Use Your Information
We use the information we collect to: • Provide, maintain, and improve the App • Process ticket purchases and manage bookings • Send booking confirmations and event reminders • Display nearby events based on your location • Manage your Coins & Rewards balance • Facilitate communication between users and organizers • Prevent fraud and ensure platform security • Comply with legal obligations under EU/Spanish law We do not sell your personal data to third parties.
🔗
3. Information Sharing
We may share your information with: • Event Organizers: your name and booking details are shared with the organizer of events you book, solely for check-in and event management purposes • Stripe: payment processing. Stripe's Privacy Policy applies to payment data • Firebase (Google): our cloud infrastructure provider for authentication, database storage, and push notifications • Legal Authorities: when required by law, court order, or to protect the safety of users We do not share your data with advertisers or marketing companies.
📍
4. Location Data
Where We Go requests access to your device's location to show you nearby events. Location access is: • Optional — the App works without location permission, but nearby event features will be limited • Only collected while using the App (foreground only) • Never sold to third parties or used for advertising You can revoke location permission at any time in your device settings.
💳
5. Payment Data & Security
All payment transactions are processed by Stripe, a PCI-DSS compliant payment processor. Where We Go: • Does NOT store your credit card or banking details • Does NOT have access to your full card number • Retains only transaction references for booking records A 5% service fee is applied to each transaction. For payment-related questions, contact: sales@diamondabstractproject.com
🔒
6. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including: • Encrypted data transmission (HTTPS/TLS) • Firebase Security Rules to restrict data access • Firebase App Check to prevent unauthorized API access • Secure authentication via Firebase Auth No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
🔔
7. Push Notifications
With your permission, we send push notifications for: • Booking confirmations • Event reminders • Coins earned • Messages from organizers You can manage notification preferences in the App under Settings > Notifications, or disable them entirely in your device settings.
👶
8. Children's Privacy
Where We Go is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, please contact us immediately at sales@diamondabstractproject.com and we will delete such information promptly.
⚖️
9. Your Rights (GDPR)
As a user in the European Union or Canary Islands, you have the following rights under the General Data Protection Regulation (GDPR): • Right of Access: request a copy of your personal data • Right to Rectification: correct inaccurate data • Right to Erasure: request deletion of your account and data • Right to Restriction: limit how we process your data • Right to Data Portability: receive your data in a structured format • Right to Object: object to processing based on legitimate interests To exercise any of these rights, contact us at: 📧 sales@diamondabstractproject.com We will respond within 30 days as required by GDPR.
🗑️
10. Account Deletion
You can request deletion of your account and all associated data at any time by using the in-app deletion request feature under Profile → Privacy & Security, or by contacting us at sales@diamondabstractproject.com with subject "Account Deletion Request". Upon deletion: • Your profile and personal data will be permanently removed • Active bookings may still be honored by organizers • Transaction records may be retained for legal/accounting purposes • Coins balance will be forfeited Deletion is permanent and cannot be undone.
🍪
11. Cookies & Tracking
The Where We Go mobile App does not use browser cookies. We use Firebase Analytics to collect anonymous usage data to improve the App experience. This data is: • Aggregated and anonymized • Not linked to your personal identity • Used solely for App performance improvements You can opt out of analytics collection in Settings > Preferences.
🔄
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will: • Notify you via push notification • Display a notice within the App • Update the "Last Updated" date at the top of this policy Your continued use of the App after changes constitutes acceptance of the updated Privacy Policy.
📧
13. Contact & Data Controller
Diamond Abstract Project is the Data Controller for your personal data. 📧 sales@diamondabstractproject.com Diamond Abstract Project Canary Islands, Spain For GDPR-related requests, please use the subject line: "GDPR Request — [Your Name]" We respond to all privacy inquiries within 30 days.