Privacy policy
Last updated:
ProSit lets somebody with a reserved Oktoberfest table offer spare seats to people they would like to sit with. To do that it needs to know a little about you, and it has to show some of it to other people. This page says exactly what, to whom, when, and for how long.
In short. No ads, no tracking, no analytics, no data sales. Your phone number is shown to one person only, and only after you and they both said yes. Other people see your public profile and whatever socials you choose to share. You can delete your account in the app at any time.
1. Who is responsible
The controller under the General Data Protection Regulation (GDPR) for the ProSit apps and this website is:
Netstrada s.r.l.Via Marche 43
60019 Senigallia (AN)
Italia / Italy
E-mail: hello@netstrada.it
PEC: nestrada@netpec.net
Write to that address for anything about your data. We have not appointed a data protection officer [check: not required under Art. 37 GDPR].
2. What we process, why, and on what legal basis
The legal bases below are the ones in Art. 6(1) GDPR: (b) the data is needed to provide the service you signed up for; (f) we have a legitimate interest, which we name, and it is not overridden by yours; (c) the law requires us to keep it.
Account and sign-in
You sign in with Apple or Google. The sign-in itself is handled by our authentication provider, Clerk. We receive a stable account identifier, your e-mail address and your name as Apple or Google pass them on. With Apple you can choose to hide your address; we then only see Apple’s relay address. We do not receive your Apple or Google password.
Why: to create and secure your account and to contact you about it. Basis: Art. 6(1)(b).
Your profile
- Display name and profile photo. Hosts choose who joins their table, so there has to be a person to choose.
- Birth year. We store the year and show other people only the resulting age. ProSit is for adults (see section 10).
- Languages you speak, and a short bio if you write one.
- Reliability figures shown on your profile: how many tables you met at, your average rating, the number of ratings, how often you cancelled an accepted seat and how often you did not show up.
Why: a request or an offer is a decision about a person. Basis: Art. 6(1)(b).
Phone number
Before you can publish an offer or send a request you verify a mobile phone number. We send a six-digit code by SMS through our SMS provider; the code is stored only in hashed form and expires. We store your verified number (in international format) and when it was verified. A number can belong to only one ProSit account.
Why: a verified number is the basic protection against throwaway and fake accounts, and it is how the person you are matched with can reach you (see section 3). Basis: Art. 6(1)(b) for sharing it after a match; Art. 6(1)(f) for using it to prevent abuse — our legitimate interest is keeping fake hosts and fake guests off the platform.
Instagram handle
Optional. If you add an Instagram handle you also choose, with a switch, whether to share it. Only when the switch is on is the handle shown — to the host of a table you ask to join, and to the one person you are matched with. Sharing nothing is always allowed. Basis: Art. 6(1)(b).
Offers (if you host)
The tent, date and time, number of seats, the price per seat you paid, what a seat includes, your group’s size, age range, languages and vibe, a headline and a description, and the offer’s status. Offers are visible to every signed-in user. Basis: Art. 6(1)(b).
Requests (if you ask to join)
The offer you asked for, how many seats, your introduction message and, for each person you bring along, the name, age, languages and an optional note you enter. Please only enter details about friends who are happy for the host to see them. We also keep each request’s history (sent, opened, accepted, declined, met, and so on, with times) and, for hosts, an optional note when declining. Basis: Art. 6(1)(b).
Meeting at the table, and ratings
At the table the host scans a QR code on the guest’s phone, or types a six-digit code. The code is generated from a secret, is valid for about a minute and contains no personal data. We record that and when the two of you met. Only people who provably met can rate each other: a rating is 1 to 5 stars with an optional comment, and is shown on the rated person’s profile. Basis: Art. 6(1)(b), and Art. 6(1)(f) — ratings from real meetings keep the platform trustworthy for everyone.
Reports and blocking
You can report an offer or a person. A report stores who reported, what, the reason and your description, and is read by a person at ProSit. We may suspend an account that breaks the terms. Basis: Art. 6(1)(f) — our legitimate interest, and yours, is safety and preventing fraud.
Credits and purchases
Sending a request uses a credit; credits are sold as in-app purchases through the App Store or Google Play. Apple or Google process the payment; we never see your card or bank details. We receive and store the product you bought, the store’s transaction id or purchase token, the platform and the time, plus a ledger of every credit added, used, returned or revoked. When a store tells us a purchase was refunded, we record it and remove those credits. Basis: Art. 6(1)(b); Art. 6(1)(f) to detect refund abuse; Art. 6(1)(c) where tax or commercial law requires records to be kept [check: statutory retention under Italian law].
Tents you follow, and push notifications
If you follow a tent we store that, to tell you when a table opens there. If you allow notifications we store your device’s push token, its platform (iOS or Android) and its language setting. Notifications are delivered by Apple (APNs) or Google (Firebase Cloud Messaging). They never contain a phone number or a social handle — only a short message and the ids the app needs to open the right screen. Basis: Art. 6(1)(b).
Server logs and backups
Our servers keep technical logs to run the service and to find faults and attacks. The application log records, per request, the method, path, response status, duration and a request id, but not your IP address. The web server in front of it records a standard access log that does include the IP address, time, requested address and the app or browser’s user agent. IP addresses are also used briefly in memory to rate-limit requests. Access logs are rotated and overwritten automatically [state a concrete maximum period, e.g. 14 days; today rotation is by size]. The database is backed up every night; backups are kept for 14 days and then deleted. Basis: Art. 6(1)(f) — our legitimate interest is a secure, working service.
This website
This website sets no cookies, loads no scripts, fonts or images from other companies and runs no analytics. If you pick a language with the language button, your browser remembers that choice locally; it is never sent to us. The hosting provider serving it keeps a technical access log (IP address, time, requested page, user agent) [confirm the log retention of both: the site is served by our server at Hetzner (Germany) from files stored with DigitalOcean Spaces in Frankfurt]. Basis: Art. 6(1)(f).
3. Who sees what, and when
Nobody sees your phone number before a mutual yes. Contact details are revealed to exactly one counterpart, and only for the table you were matched on.
| Moment | The host sees of the guest | The guest sees of the host |
|---|---|---|
| Browsing | — | Public profile. No contact details. |
| A request is sent | Public profile, the request and the socials the guest chose to share | — |
| The host accepts | Phone number and shared socials | Phone number and shared socials |
| Declined, expired, withdrawn, cancelled | Nothing more | Nothing |
- Public profile — visible to any signed-in ProSit user: display name, photo, age (not the birth year), languages, bio, reliability figures, recent ratings and when you joined. It never contains your phone number, e-mail address or social handles.
- One phone number per date. When a host accepts you, your other open requests for that date are withdrawn automatically, so at most one host per date ever sees your number.
- The reveal expires. The other person’s contact details stop being shown 24 hours after the table ends. The request stays in your history; the contact card on it does not. (Anything the other person wrote down or saved on their phone in the meantime is, of course, outside our control.)
- Buying credits never unlocks anybody’s contact details.
- A host never sees how many other tables a guest asked, or where the guest is.
4. Service providers and other recipients
We use these providers. Those acting on our behalf are bound by a data processing agreement under Art. 28 GDPR [confirm a DPA is signed with each processor].
| Provider | What for | Where |
|---|---|---|
| Hetzner Online GmbH, Gunzenhausen, Germany | Hosting of our servers and database (processor) | Germany (Nuremberg) |
| Clerk, Inc., USA | Sign-in and account authentication (processor) | USA [check region / DPF] |
| Twilio Inc., USA | Sending the SMS verification code to your phone number (processor) | USA [check region / DPF] |
| Apple Inc. / Apple Distribution International Ltd., Ireland | Sign in with Apple, App Store purchases (Apple is the seller of the credits), push notifications (APNs) | EU / USA |
| Google LLC / Google Ireland Ltd. | Sign in with Google, Google Play purchases (Google is the seller of the credits), push notifications (Firebase Cloud Messaging) | EU / USA |
| DigitalOcean, LLC, USA | Storage of this website's files (processor) | Germany (Frankfurt) |
For in-app purchases Apple and Google act as merchant of record under their own privacy policies; they process your payment details, not us. Other ProSit users receive the data described in section 3. We disclose data to authorities only when the law obliges us to. We never sell personal data.
5. Transfers outside the EU
Our servers are in Germany. Some providers above are based in the USA. Where personal data goes there, the transfer relies on the provider’s certification under the EU–US Data Privacy Framework (Art. 45 GDPR) or on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR) [confirm the mechanism for each US provider].
6. How long we keep data
| Data | Kept |
|---|---|
| Account, profile, phone number, Instagram handle | As long as your account exists |
| The other person’s contact details on a matched request | Shown until 24 hours after the table ends |
| Offers, requests and their history, follows, credit ledger, purchase records, push tokens | As long as your account exists; push tokens are removed earlier when the store reports them invalid |
| Phone verification codes | Hashed; valid for minutes; deleted with the account |
| Ratings you gave | Kept after you delete your account, without your name or any link to you |
| Reports | Reports you filed are deleted with your account. Reports about you are kept as long as needed to handle them [define a period] |
| Server access logs | Rotated automatically [concrete period] |
| Backups | 14 days |
7. Deleting your account
In the app: Profile → Delete account. It takes effect immediately. If you no longer have the app, see how to request deletion by e-mail, which also explains exactly what is deleted and what is not. Deleted data disappears from backups when they expire, at the latest after 14 days.
8. Your rights
You have the right to:
- access the data we hold about you (Art. 15 GDPR);
- have it corrected (Art. 16) — most of it you can edit yourself in the app;
- have it erased (Art. 17) — see section 7;
- restrict its processing (Art. 18);
- receive it in a portable format (Art. 20);
- object to processing based on legitimate interests, on grounds relating to your situation (Art. 21).
Write to hello@netstrada.it. We answer within one month.
You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). As Netstrada s.r.l. is established in Italy, our lead supervisory authority is:
Garante per la protezione dei dati personaliPiazza Venezia 11, 00187 Roma, Italy
www.garanteprivacy.it
You may also complain to the supervisory authority of the EU country where you live or work, or where you believe the infringement took place.
9. No tracking, no ads, no analytics
The ProSit apps contain no advertising, no analytics or crash-reporting SDKs and no tracking across apps or websites. The Android app includes Google’s Firebase Cloud Messaging library for the sole purpose of delivering push notifications. We do not build advertising profiles and we do not sell or rent personal data. Your contact details are never sent to analytics, push payloads or the app stores.
10. Age, required data, automated decisions, changes
- Age. ProSit is only for people aged 18 or over. Oktoberfest tents serve alcohol; the app does not accept a birth year under 18.
- Required data. You can browse without a phone number or a complete profile. To publish an offer or send a request you need a verified phone number, a profile photo, a display name, at least one language and a birth year. Without them we cannot provide those parts of the service.
- No automated decisions. Offers are sorted by a simple match (shared languages, age range, how soon); that is a sort order, not a decision about you. Whom to accept is always decided by a person.
- Changes. If this policy changes we update the date at the top, and tell you in the app when the change matters.