Haps
Haps

Privacy Policy

Effective Date: August 28, 2026

Overview

This privacy policy applies to the Haps app (hereby referred to as "Application") for mobile devices that was created by haps events (hereby referred to as "Service Provider") as a Free service. This service is intended for use "AS IS".

Information Collection and Use

The Application collects information when you download and use it. This information may include information such as:

  • • Your device's Internet Protocol address (e.g. IP address)
  • • The pages of the Application that you visit, the time and date of your visit, the time spent on those pages
  • • The time spent on the Application
  • • The operating system you use on your mobile device

Categories of Data We Collect

  • Account data: email address, password credentials (hashed), display name, username, date of birth, and — where you use social sign-in — the basic profile data that provider returns.
  • Profile & preference data: avatar, bio, interests, privacy settings, notification preferences, saved filters, blocked users, and close-friends lists.
  • Content you create: posts, stories, comments, reviews, memos, event and group listings, forum topics, polls, and any media (photos, video, voice notes) you upload, along with captions, tags, mentions, and optional location metadata.
  • Communications: direct messages, group chats, story replies, message requests, and reports you submit. Messages are not end-to-end encrypted.
  • Social graph: who you follow, follow requests, group memberships, event RSVPs, saves, likes, check-ins, and tap-to-connect handshakes.
  • Ticketing & transactions: tickets purchased, transferred, listed or resold, promo codes used, refund requests, check-in scans, and payment status. Card details are handled by Stripe and never stored by us.
  • Verification data: where you choose to verify your age or identity, images of an identity document and a selfie, processed for verification and retained only as long as needed to evidence the check.
  • Device & integrity signals: a device fingerprint derived from platform, screen, timezone, language and user-agent, plus login history, used to detect fraud, duplicate accounts, and evasion of enforcement actions.
  • Usage & analytics: pages viewed, time spent on each screen, buttons and controls tapped (labels only — never the contents of what you type), feature usage, event views, and crash/diagnostic data.
  • Device permissions: camera, photo library, microphone, precise location, and push notification tokens — each requested only when you use the related feature, and revocable in your device settings.

How & Why We Use Data (Legal Bases)

  • To perform our contract with you: creating your account, delivering events, messaging, tickets, check-in, and refunds.
  • Legitimate interests: keeping the platform safe (moderation, anti-fraud, anti-scalping, ban-evasion detection), measuring and improving features, and securing our systems.
  • Consent: precise location, camera/microphone/photos access, push notifications, marketing messages, and identity verification. You may withdraw consent at any time in-app or via device settings.
  • Legal obligation: tax and financial records, responding to lawful requests, and child-safety obligations.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

Public & Shared Content

Much of the Application is social by design. Your username, avatar, bio, public posts, stories, reviews, event listings, group activity and attendance may be visible to other users, and to anyone who can view a public group or event — including people who are not registered. Content shared to others, re-shared, screenshotted, or already delivered may persist even after you delete the original. Consider your privacy settings before posting, and never post someone else's location or personal details without their consent.

Location Services

The Application collects your device's location, which helps the Service Provider determine your approximate geographical location and make use of in below ways:

  • Geolocation Services: The Service Provider utilizes location data to provide features such as personalized content, relevant recommendations, and location-based services.
  • Analytics and Improvements: Aggregated and anonymized location data helps the Service Provider to analyze user behavior, identify trends, and improve the overall performance and functionality of the Application.
  • Third-Party Services: Periodically, the Service Provider may transmit anonymized location data to external services. These services assist them in enhancing the Application and optimizing their offerings.

Artificial Intelligence

The Application uses Artificial Intelligence (AI) technologies to provide and safeguard certain features:

  • Content moderation: Posts, stories, comments, and messages reported by users, as well as newly uploaded media, may be automatically scanned by AI systems to detect content that violates our Community Guidelines (e.g. graphic violence, hate speech, spam). Flagged content is reviewed and may be blurred, removed, or escalated to human moderators.
  • Video analysis: When you upload a video, your device samples a few still frames from it (near the start, middle and end) and, where the video contains speech, we transcribe its audio. Those frames and the transcript are analysed by the same automated safety scan applied to photos, so video is reviewed rather than published unchecked. Sampled frames are internal moderation records, are never shown to other users, and are deleted along with the content they came from.
  • Content understanding: The same scan also derives a short list of descriptive keywords about what a photo or video depicts, and — where the media contains speech — a transcript of that audio. These are used only to rank and recommend content, to improve search, and to help our moderation queue. They are never shown to other users as facts about your content, and they are deleted with the content they belong to.
  • Search: Your search queries may be processed by AI to understand intent and return more relevant events, people, and groups.
  • Age verification: When you verify your age for 18+ events, images of your ID document and selfie are processed by AI to confirm your age. These images are used solely for verification and are not shared with other users.

AI processing is performed via our platform sub-processor, base44 AI (Base44 / Wix.com Ltd), under contractual confidentiality obligations. Your data is not used to train third-party AI models.

Communications

The Service Provider may use the information you provided to contact you from time to time to provide you with important information, required notices and marketing promotions. For a better experience, while using the Application, the Service Provider may require you to provide us with certain personally identifiable information. The information that the Service Provider request will be retained by them and used as described in this privacy policy.

Third Party Access

Only aggregated, anonymized data is periodically transmitted to external services to aid the Service Provider in improving the Application and their service. The Service Provider may share your information with third parties in the ways that are described in this privacy statement.

The Service Provider may disclose User Provided and Automatically Collected Information:

  • • As required by law, such as to comply with a subpoena, or similar legal process
  • • When they believe in good faith that disclosure is necessary to protect their rights, protect your safety or the safety of others, investigate fraud, or respond to a government request
  • • With their trusted services providers who work on their behalf, do not have an independent use of the information we disclose to them, and have agreed to adhere to the rules set forth in this privacy statement
  • • With event organisers: when you RSVP to, purchase a ticket for, or check in to an event, your name, email address, and ticket details are shared with that event's organiser strictly for entry management and check-in purposes

Service Providers & Sub-Processors

We rely on a small number of vetted providers, each bound by contractual confidentiality and data-protection obligations:

  • Base44 / Wix.com Ltd — hosting, database, authentication, storage, and AI features
  • Stripe — payment processing, refunds, and fraud prevention (Stripe is the controller of your payment data)
  • Google Maps & OpenStreetMap/CARTO — map tiles, geocoding, and place data
  • Weather data providers — forecasts for event locations and dates
  • Apple & Google — push notification delivery and app distribution

Automated Decision-Making

We use automated systems to rank and recommend events and content based on your interests, saves, RSVPs, interactions, and location, and to detect abuse, fraud, duplicate accounts, and enforcement evasion. In some cases these systems may automatically limit an account, freeze a group, blur media, or hide content pending human review. Where an automated action materially affects you, you may request human review by contacting us or, where offered, submitting an appeal in-app.

Analytics & Product Tracking

To understand how the Application is used and where it can be improved, we record first-party product analytics tied to your account:

  • Screen views and dwell time — which screen you opened and roughly how long you stayed before navigating away.
  • Interaction labels — the identifier of a button or control you tapped (for example "like", "share", "open_filters"). We capture the label only, never the text you type, your message contents, or search terms typed into a field.
  • Content and event views — when you open an event, post, story or profile, so creators and organisers can see how many views their content received.
  • Feature usage and funnels — for example view → RSVP → ticket purchase → check-in, used to measure conversion and diagnose drop-off.
  • Diagnostics — error and performance data, including failed requests, so we can fix faults.

These records are stored on our own infrastructure, are accessible only to our administrators, and are not sold, shared with advertising networks, or used for cross-context behavioural advertising. We do not embed third-party ad or social tracking pixels. Your search history is kept locally on your device and can be cleared from the search screen.

Attendance, Check-In & Location Verification

Where you have granted location permission, the Application may compare your device's location with the location of events you have saved, RSVP'd to, or hold a ticket for, in order to record that you were actually present. This produces an attendance record noting the event, the time, and the signal that confirmed it (proximity, door scan, RSVP, or ticket). We record whether you were near the venue — we do not keep a continuous history of your movements, and we do not share your live location with organisers or other users.

When your ticket is scanned at the door, we record the scan time, the method (QR, NFC, or manual override), a short admission reference, and the name of the staff member who admitted you. Repeat presentations of an already-used ticket are counted to detect pass-back and screenshot fraud. This information is visible to the organiser of that event and to you on your ticket. You can withdraw location permission at any time in your device settings; you will still be able to check in manually at the door.

Finding Friends from Your Contacts

If you choose to use "Find your friends", your device asks you which contacts to share and then converts each contact's email address into an irreversible one-way code (a SHA-256 hash) on your device. Only those codes are sent to us. We generate the same code for existing accounts and tell you which of your contacts already have one.

  • We never receive your address book. No names, phone numbers or email addresses of your contacts are transmitted.
  • We store nothing. The codes are used to answer one request and are then discarded — there is no contact list, match history or "shadow profile" kept about people who are not users.
  • Codes for contacts who aren't on Haps are simply ignored, so we learn nothing about them.
  • Nobody is contacted automatically. No invites, follows, or messages are sent on your behalf — you choose who to follow, and private accounts still receive a follow request.
  • You can refuse or stop at any time, and you can prevent others from finding you this way with "Let contacts find me" in Settings → Permissions. Turning it off means your account is skipped even when someone has your email saved.

Because a one-way code is only as private as the value behind it, we treat these codes as personal information while we hold them and discard them immediately after matching. Legal basis: your consent, which you may withdraw at any time as described above.

Reviews & Ratings

After an event you actually attended, we may invite you to rate it. Your rating and any written comment are stored against the event together with the attendance signal that qualified you to review it. Ratings from geo-verified attendance are also aggregated into a private quality score for the organising group. That aggregate is used internally for trust and safety and quality purposes and is not displayed publicly unless and until we announce otherwise. You can delete your own review at any time.

Notifications, Emails & Reminders

With your permission we store a push notification token for your device so we can deliver event reminders, weather alerts for events you're attending, message and social notifications, ticket confirmations, and periodic digests or re-engagement reminders if you have been inactive. Tokens are tied to your account and deleted when you revoke permission, sign out of that device, or delete your account. Notification types can be tuned in the app's notification settings, permissions can be revoked in your device settings, and transactional messages (ticket receipts, refunds, safety and account notices) will still be sent because they are necessary to provide the service.

What Event Organisers Can See

Organisers, their approved co-organisers, and connected Organiser Portal sessions can access data about their own events only:

  • • Attendee name, email, ticket type, order reference, purchase date and check-in status for their event
  • • Aggregated event performance — views over time, RSVPs, tickets sold by date, conversion funnels, promo-code performance, and door-throughput statistics
  • • Refund requests and support cases raised about their event, including the messages you send in that case
  • • Answers you give to a group's join questions, and your membership status

Organisers act as independent controllers of the attendee data they receive and must use it only for running that event. They may not add you to unrelated marketing lists. Organisers cannot see your messages with other users, your other events, your location, or your device signals.

Support Cases & Disputes

If you raise an issue about a ticket, a case is created containing your name, ticket and order details, the category of issue, and the messages and images exchanged. Cases are handled first by the event organiser or their staff — who may respond under a staff display name rather than their personal profile — and may be escalated to us if unresolved. We retain cases as a record of the dispute and any refund decision.

Safety, Integrity & Enforcement Records

To keep the platform safe we keep enforcement records: warnings, suspensions and bans, moderation decisions and appeals, reports you make or that are made about you, admin action logs, and device signatures with the accounts seen on them. These are used to detect duplicate accounts, ban evasion, scalping and fraud, and are retained after content or an account is deleted so that enforcement cannot be reset by deleting and re-registering. Access is limited to our administrators.

Your Privacy Rights

Depending on where you live (including under the GDPR, UK GDPR, CCPA/CPRA, and the Australian Privacy Act), you may have the right to:

  • • Access a copy of the personal information we hold about you
  • • Correct inaccurate or incomplete information
  • • Request deletion of your account and associated data (Settings → Account Actions → Delete Account); you can cancel the request in Settings during the 30-day recovery window
  • • Object to or restrict certain processing, including profiling used for recommendations
  • • Withdraw consent for location, camera, microphone, notifications, or marketing
  • • Request portability of the data you provided to us
  • • Lodge a complaint with your local data protection authority (in Australia, the OAIC)

We will respond within the timeframe required by applicable law (generally 30 days) and will never discriminate against you for exercising these rights. Some data must be retained where we have a legal obligation, an unresolved dispute or chargeback, or a safety/enforcement record to preserve.

International Transfers

Your information may be stored and processed in countries other than your own, including the United States, Israel, and the European Union, where our providers operate. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses and equivalent transfer mechanisms.

Cookies & Local Storage

The Application uses cookies, local storage, and cached data to keep you signed in, remember your filters, drafts, theme and onboarding progress, and to cache map tiles and images for offline and performance reasons. These are strictly functional — we do not use third-party advertising trackers. Clearing app data or uninstalling the Application removes them.

Opt-Out & Choices

You can turn off location, camera, microphone, and notification permissions at any time in your device settings, adjust visibility and messaging controls in the app's privacy settings, mute or block other users, and opt out of non-essential emails. You can stop all collection of information by uninstalling the Application, using the standard uninstall process available on your device or app marketplace. Some features will not function without the related permission.

Data Breach Notification

If we become aware of a data breach likely to result in serious harm, we will notify affected users and the relevant regulator without undue delay, as required by applicable law, and describe the steps we are taking in response.

Data Retention Policy

We keep data only as long as we need it for the purpose it was collected, or as long as the law requires. Indicative periods:

  • Account, profile and content: retained while your account is active; deletion requests have a 30-day cancellation window, followed by processing subject to applicable retention obligations and exceptions. Contact us for the status of a request.
  • Stories: automatically expire and are removed 24 hours after posting
  • Messages: until deleted by a participant; copies already delivered to a recipient may remain in their thread
  • Moderation inputs (sampled video frames, transcripts, derived keywords): deleted with the content they came from
  • Tickets, payments, refunds and tax records: retained as required by financial and tax law (generally up to 7 years)
  • Attendance, check-in and review records: retained for the lifetime of the event record and dispute window
  • Analytics and diagnostics: retained in identifiable form only as long as needed for product analysis, then aggregated
  • Enforcement, audit and device-signature records: retained beyond account deletion where needed to prevent ban evasion, fraud, and repeat harm
  • Verification images: kept only as long as needed to evidence the check, then deleted

You can delete your account and associated data yourself at any time from within the Application via Settings → Account Actions → Delete Account. Alternatively, you may contact them at 7chancess7@gmail.com and they will respond in a reasonable time.

Children

The Service Provider does not use the Application to knowingly solicit data from or market to children under the age of 13. The Service Provider does not knowingly collect personally identifiable information from children. The Service Provider encourages all children to never submit any personally identifiable information through the Application and/or Services. The Service Provider encourage parents and legal guardians to monitor their children's Internet usage and to help enforce this Policy by instructing their children never to provide personally identifiable information through the Application and/or Services without their permission.

If you have reason to believe that a child has provided personally identifiable information to the Service Provider through the Application and/or Services, please contact the Service Provider at 7chancess7@gmail.com so that they will be able to take the necessary actions. You must also be at least 16 years of age to consent to the processing of your personally identifiable information in your country (in some countries we may allow your parent or guardian to do so on your behalf).

Security

The Service Provider is concerned about safeguarding the confidentiality of your information. The Service Provider provides physical, electronic, and procedural safeguards to protect information the Service Provider processes and maintains.

Changes to This Policy

This Privacy Policy may be updated from time to time for any reason. The Service Provider will notify you of any changes to the Privacy Policy by updating this page with the new Privacy Policy. You are advised to consult this Privacy Policy regularly for any changes, as continued use is deemed approval of all changes.

Your Consent

By using the Application, you are consenting to the processing of your information as set forth in this Privacy Policy now and as amended by us.

Contact Us

If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at 7chancess7@gmail.com

Effective Date: August 28, 2026