Privacy policy

Last updated:

ProSit lets somebody with a reserved Oktoberfest table offer spare seats to people they would like to sit with. To do that it needs to know a little about you, and it has to show some of it to other people. This page says exactly what, to whom, when, and for how long.

In short. No ads, no tracking, no analytics, no data sales. Your phone number is shown to one person only, and only after you and they both said yes. Other people see your public profile and whatever socials you choose to share. You can delete your account in the app at any time.

1. Who is responsible

The controller under the General Data Protection Regulation (GDPR) for the ProSit apps and this website is:

Netstrada s.r.l.
Via Marche 43
60019 Senigallia (AN)
Italia / Italy
E-mail: hello@netstrada.it
PEC: nestrada@netpec.net

Write to that address for anything about your data. We have not appointed a data protection officer [check: not required under Art. 37 GDPR].

2. What we process, why, and on what legal basis

The legal bases below are the ones in Art. 6(1) GDPR: (b) the data is needed to provide the service you signed up for; (f) we have a legitimate interest, which we name, and it is not overridden by yours; (c) the law requires us to keep it.

Account and sign-in

You sign in with Apple or Google. The sign-in itself is handled by our authentication provider, Clerk. We receive a stable account identifier, your e-mail address and your name as Apple or Google pass them on. With Apple you can choose to hide your address; we then only see Apple’s relay address. We do not receive your Apple or Google password.

Why: to create and secure your account and to contact you about it. Basis: Art. 6(1)(b).

Your profile

Why: a request or an offer is a decision about a person. Basis: Art. 6(1)(b).

Phone number

Before you can publish an offer or send a request you verify a mobile phone number. We send a six-digit code by SMS through our SMS provider; the code is stored only in hashed form and expires. We store your verified number (in international format) and when it was verified. A number can belong to only one ProSit account.

Why: a verified number is the basic protection against throwaway and fake accounts, and it is how the person you are matched with can reach you (see section 3). Basis: Art. 6(1)(b) for sharing it after a match; Art. 6(1)(f) for using it to prevent abuse — our legitimate interest is keeping fake hosts and fake guests off the platform.

Instagram handle

Optional. If you add an Instagram handle you also choose, with a switch, whether to share it. Only when the switch is on is the handle shown — to the host of a table you ask to join, and to the one person you are matched with. Sharing nothing is always allowed. Basis: Art. 6(1)(b).

Offers (if you host)

The tent, date and time, number of seats, the price per seat you paid, what a seat includes, your group’s size, age range, languages and vibe, a headline and a description, and the offer’s status. Offers are visible to every signed-in user. Basis: Art. 6(1)(b).

Requests (if you ask to join)

The offer you asked for, how many seats, your introduction message and, for each person you bring along, the name, age, languages and an optional note you enter. Please only enter details about friends who are happy for the host to see them. We also keep each request’s history (sent, opened, accepted, declined, met, and so on, with times) and, for hosts, an optional note when declining. Basis: Art. 6(1)(b).

Meeting at the table, and ratings

At the table the host scans a QR code on the guest’s phone, or types a six-digit code. The code is generated from a secret, is valid for about a minute and contains no personal data. We record that and when the two of you met. Only people who provably met can rate each other: a rating is 1 to 5 stars with an optional comment, and is shown on the rated person’s profile. Basis: Art. 6(1)(b), and Art. 6(1)(f) — ratings from real meetings keep the platform trustworthy for everyone.

Reports and blocking

You can report an offer or a person. A report stores who reported, what, the reason and your description, and is read by a person at ProSit. We may suspend an account that breaks the terms. Basis: Art. 6(1)(f) — our legitimate interest, and yours, is safety and preventing fraud.

Credits and purchases

Sending a request uses a credit; credits are sold as in-app purchases through the App Store or Google Play. Apple or Google process the payment; we never see your card or bank details. We receive and store the product you bought, the store’s transaction id or purchase token, the platform and the time, plus a ledger of every credit added, used, returned or revoked. When a store tells us a purchase was refunded, we record it and remove those credits. Basis: Art. 6(1)(b); Art. 6(1)(f) to detect refund abuse; Art. 6(1)(c) where tax or commercial law requires records to be kept [check: statutory retention under Italian law].

Tents you follow, and push notifications

If you follow a tent we store that, to tell you when a table opens there. If you allow notifications we store your device’s push token, its platform (iOS or Android) and its language setting. Notifications are delivered by Apple (APNs) or Google (Firebase Cloud Messaging). They never contain a phone number or a social handle — only a short message and the ids the app needs to open the right screen. Basis: Art. 6(1)(b).

Server logs and backups

Our servers keep technical logs to run the service and to find faults and attacks. The application log records, per request, the method, path, response status, duration and a request id, but not your IP address. The web server in front of it records a standard access log that does include the IP address, time, requested address and the app or browser’s user agent. IP addresses are also used briefly in memory to rate-limit requests. Access logs are rotated and overwritten automatically [state a concrete maximum period, e.g. 14 days; today rotation is by size]. The database is backed up every night; backups are kept for 14 days and then deleted. Basis: Art. 6(1)(f) — our legitimate interest is a secure, working service.

This website

This website sets no cookies, loads no scripts, fonts or images from other companies and runs no analytics. If you pick a language with the language button, your browser remembers that choice locally; it is never sent to us. The hosting provider serving it keeps a technical access log (IP address, time, requested page, user agent) [confirm the log retention of both: the site is served by our server at Hetzner (Germany) from files stored with DigitalOcean Spaces in Frankfurt]. Basis: Art. 6(1)(f).

3. Who sees what, and when

Nobody sees your phone number before a mutual yes. Contact details are revealed to exactly one counterpart, and only for the table you were matched on.

What other people see of you
MomentThe host sees of the guestThe guest sees of the host
BrowsingPublic profile. No contact details.
A request is sentPublic profile, the request and the socials the guest chose to share
The host acceptsPhone number and shared socialsPhone number and shared socials
Declined, expired, withdrawn, cancelledNothing moreNothing

4. Service providers and other recipients

We use these providers. Those acting on our behalf are bound by a data processing agreement under Art. 28 GDPR [confirm a DPA is signed with each processor].

ProviderWhat forWhere
Hetzner Online GmbH, Gunzenhausen, GermanyHosting of our servers and database (processor)Germany (Nuremberg)
Clerk, Inc., USASign-in and account authentication (processor)USA [check region / DPF]
Twilio Inc., USASending the SMS verification code to your phone number (processor)USA [check region / DPF]
Apple Inc. / Apple Distribution International Ltd., IrelandSign in with Apple, App Store purchases (Apple is the seller of the credits), push notifications (APNs)EU / USA
Google LLC / Google Ireland Ltd.Sign in with Google, Google Play purchases (Google is the seller of the credits), push notifications (Firebase Cloud Messaging)EU / USA
DigitalOcean, LLC, USAStorage of this website's files (processor)Germany (Frankfurt)

For in-app purchases Apple and Google act as merchant of record under their own privacy policies; they process your payment details, not us. Other ProSit users receive the data described in section 3. We disclose data to authorities only when the law obliges us to. We never sell personal data.

5. Transfers outside the EU

Our servers are in Germany. Some providers above are based in the USA. Where personal data goes there, the transfer relies on the provider’s certification under the EU–US Data Privacy Framework (Art. 45 GDPR) or on the European Commission’s standard contractual clauses (Art. 46(2)(c) GDPR) [confirm the mechanism for each US provider].

6. How long we keep data

DataKept
Account, profile, phone number, Instagram handleAs long as your account exists
The other person’s contact details on a matched requestShown until 24 hours after the table ends
Offers, requests and their history, follows, credit ledger, purchase records, push tokensAs long as your account exists; push tokens are removed earlier when the store reports them invalid
Phone verification codesHashed; valid for minutes; deleted with the account
Ratings you gaveKept after you delete your account, without your name or any link to you
ReportsReports you filed are deleted with your account. Reports about you are kept as long as needed to handle them [define a period]
Server access logsRotated automatically [concrete period]
Backups14 days

7. Deleting your account

In the app: Profile → Delete account. It takes effect immediately. If you no longer have the app, see how to request deletion by e-mail, which also explains exactly what is deleted and what is not. Deleted data disappears from backups when they expire, at the latest after 14 days.

8. Your rights

You have the right to:

Write to hello@netstrada.it. We answer within one month.

You have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). As Netstrada s.r.l. is established in Italy, our lead supervisory authority is:

Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma, Italy
www.garanteprivacy.it

You may also complain to the supervisory authority of the EU country where you live or work, or where you believe the infringement took place.

9. No tracking, no ads, no analytics

The ProSit apps contain no advertising, no analytics or crash-reporting SDKs and no tracking across apps or websites. The Android app includes Google’s Firebase Cloud Messaging library for the sole purpose of delivering push notifications. We do not build advertising profiles and we do not sell or rent personal data. Your contact details are never sent to analytics, push payloads or the app stores.

10. Age, required data, automated decisions, changes