TAGZ Privacy Policy
Last updated: September 2, 2026
1. Controller
TAGZ Social
John Brandauer
Buchbrunn 21
9141 Eberndorf
office@tagz-social.com
This privacy policy explains how we process your personal data when you use the TAGZ app, in accordance with the EU General Data Protection Regulation (GDPR/DSGVO).
Website and Private-Beta Waitlist / Website und Private-Beta-Warteliste
What we process / Welche Daten wir verarbeiten
EN: When you join the waitlist, we process your email address, your optional preferred handle, your language, the applicable consent and policy versions, the registration time, and your waitlist position. At application and database level, we store only a keyed pseudonymous digest of the connection IP address for one 15-minute abuse-prevention window; the raw IP address and browser user agent are not attached to your waitlist entry. Google Cloud may separately create technical request and security logs, including connection metadata, for service operation and security. The project’s current default log retention is 30 days.
DE: Wenn du dich in die Warteliste einträgst, verarbeiten wir deine E-Mail-Adresse, optional deinen gewünschten Benutzernamen, deine Sprache, die geltenden Einwilligungs- und Datenschutzerklärungsversionen, den Registrierungszeitpunkt und deinen Wartelistenplatz. Auf Anwendungs- und Datenbankebene speichern wir für ein 15-minütiges Missbrauchsschutz-Fenster nur einen pseudonymisierten, geheimnisgebundenen Prüfwert der Verbindungs-IP-Adresse; die rohe IP-Adresse und der Browser-User-Agent werden nicht mit deinem Wartelisteneintrag verknüpft. Google Cloud kann davon getrennt technische Anfrage- und Sicherheitsprotokolle einschließlich Verbindungsmetadaten für Betrieb und Sicherheit erzeugen. Die aktuelle Standard-Aufbewahrungsdauer des Projekts beträgt 30 Tage.
Purpose and legal basis / Zweck und Rechtsgrundlage
EN: We use these data to manage the Vienna private-beta waitlist and email you when TestFlight or Google Play access is available. The legal basis is your consent under Art. 6(1)(a) GDPR. You may withdraw consent at any time by emailing office@tagz-social.com, without affecting processing carried out before withdrawal. Abuse prevention is based on our legitimate interest under Art. 6(1)(f) GDPR in protecting the form and our infrastructure.
DE: Wir verwenden diese Daten, um die Wiener Private-Beta-Warteliste zu verwalten und dich per E-Mail zu informieren, sobald ein TestFlight- oder Google-Play-Zugang verfügbar ist. Rechtsgrundlage ist deine Einwilligung nach Art. 6 Abs. 1 lit. a DSGVO. Du kannst sie jederzeit per E-Mail an office@tagz-social.com widerrufen; die Rechtmäßigkeit der Verarbeitung bis zum Widerruf bleibt unberührt. Die Missbrauchsabwehr beruht auf unserem berechtigten Interesse nach Art. 6 Abs. 1 lit. f DSGVO, das Formular und unsere Infrastruktur zu schützen.
Storage, recipients and retention / Speicherung, Empfänger und Dauer
EN: Firebase and Google Cloud process the waitlist data for us as service providers. The safeguards described in section 3 also apply. Waitlist entries are scheduled for automatic deletion 12 months after the latest registration or earlier after withdrawal, unless a legal obligation requires limited further retention. Short-lived abuse-prevention records are no longer used after their 15-minute window and are removed by scheduled cleanup and database expiry controls.
DE: Firebase und Google Cloud verarbeiten die Wartelistendaten für uns als Dienstleister. Es gelten auch die in Abschnitt 3 beschriebenen Garantien. Wartelisteneinträge werden 12 Monate nach der letzten Registrierung zur automatischen Löschung vorgesehen, nach einem Widerruf bereits früher, soweit keine gesetzliche Pflicht eine begrenzte weitere Aufbewahrung verlangt. Kurzlebige Missbrauchsschutz-Datensätze werden nach ihrem 15-Minuten-Fenster nicht mehr verwendet und durch geplante Bereinigung sowie Ablaufregeln der Datenbank entfernt.
Local storage and sharing / Lokale Speicherung und Teilen
EN: The marketing website uses no analytics or marketing cookies. It stores only your chosen language on your device after you use the language switch. Email addresses, handles and waitlist positions are not stored in browser storage. WhatsApp receives data only when you deliberately click the WhatsApp share button; the shared link contains no email, handle or waitlist identifier.
DE: Die Marketing-Website verwendet keine Analyse- oder Marketing-Cookies. Erst wenn du den Sprachumschalter verwendest, wird nur deine gewählte Sprache auf deinem Gerät gespeichert. E-Mail-Adressen, Benutzernamen und Wartelistenplätze werden nicht im Browser-Speicher abgelegt. WhatsApp erhält erst Daten, wenn du bewusst den WhatsApp-Teilen-Button anklickst; der geteilte Link enthält weder E-Mail-Adresse noch Benutzername oder Wartelistenkennung.
2. Data We Collect and Legal Basis (DSGVO Art 13)
Account Data
- Email address, display name, profile photo, and account identifiers
- Legal basis: Contract performance (Art 6(1)(b)) — necessary to provide the TAGZ service
Signed-Out Public Browsing
- Guest Map can be used without an account. It returns sanitized public plan titles, descriptions, times, and approximate areas with a 4 km uncertainty radius; it does not expose exact venues, attendee lists, chat, or private media
- Guest browsing does not create an anonymous Firebase account and does not initialize PostHog analytics
- Firebase App Check verifies native guest requests. Abuse controls retain only a short-lived HMAC of transport IP, app ID, and route for up to 15 minutes; rate-limit records do not contain raw IP addresses, App Check tokens, searches, event IDs, or coordinates
- Guest event IDs, search text, coordinates, authentication intents, and App Check values are not sent to analytics or Sentry
- Legal basis: Legitimate interest (Art 6(1)(f)) — providing public discovery while preventing abuse and protecting private event data
Event and Social Content
- Events you create, join, or view; event titles, descriptions, comments, guest activity, report notes, and event locations
- Content you share into TAGZ from the system share sheet may be used to prefill event text, links, or media before you submit it
- Event chat messages and other in-app messages you send to participants
- Legal basis: Contract performance (Art 6(1)(b)) — core app functionality
Media Data
- Photos and videos you upload to profiles, events, or shared event albums
- Audio contained in user-recorded videos, such as voice or ambient sound captured with the video
- Legal basis: Contract performance (Art 6(1)(b)) — sharing event media you choose to submit
Location Data
- GPS coordinates when creating events or after you explicitly choose “Use my location” on a map; public browsing remains available without location permission
- Legal basis: Consent (Art 6(1)(a)) — via the action-bound device location permission; revocable at any time in device settings
Calendar Data
- Optional on-device calendar writes when you choose to add a joined event to your device calendar
- TAGZ checks your device calendar list locally only to find a writable calendar for that action
- TAGZ does not upload or sync your existing calendar events or calendar lists to TAGZ servers
- Legal basis: Consent (Art 6(1)(a)) — via device calendar permission and your optional action
Contact Import Data
- Optional contact phone numbers are normalized and hashed on your device only after you choose “Import contacts”
- Hashed contact values are sent under your signed-in account to find friends and prevent abuse; raw contact names and phone numbers are not stored on TAGZ servers
- Legal basis: Consent (Art 6(1)(a)) — via the action-bound device contacts permission and your optional contact import action
Purchase Data
- Subscription product identifiers, purchase status, transaction references, and entitlement state from official app marketplace billing
- Legal basis: Contract performance (Art 6(1)(b)) — activating paid organization features and purchase support
Device and Technical Data
- Device type, OS version, app version, crash reports
- Legal basis: Legitimate interest (Art 6(1)(f)) — maintaining app stability and security
Usage Analytics (PostHog)
- Opt-in interaction data linked to your TAGZ account, such as screens viewed and features used
- Featured event view and tap counts are aggregate counters and do not store who saw or tapped the featured card
- Legal basis: Consent (Art 6(1)(a)) — opt-in only; you can enable or disable this in Privacy Settings at any time
Push Notifications
- Device push tokens used to deliver notifications after you explicitly enable notifications or a reminder
- Legal basis: Consent (Art 6(1)(a)) — via the action-bound device notification permission
3. Third-Party Processors and Data Transfers
We use the following third-party service providers to operate TAGZ. Some process data in the United States under the EU-US Data Privacy Framework (DPF):
- Firebase / Google Cloud (US) — Account authentication, app database, file storage, and push-notification delivery. Transfer basis: EU-US Data Privacy Framework.
- Sentry (US) — Error tracking and crash reporting. TAGZ may send a pseudonymous account identifier for support and reliability correlation; no email, name, or username is sent by default. Transfer basis: EU-US Data Privacy Framework.
- PostHog (US) — Usage analytics (opt-in only). Transfer basis: EU-US Data Privacy Framework.
- Official app marketplace billing (US/EU as applicable) — In-app purchase and subscription processing. Transfer basis: platform privacy terms and applicable data-transfer safeguards.
We never sell your personal data. Data is shared with processors only as necessary to provide the service.
4. Data Retention
We retain your data while your account is active. When you delete your account, we delete your personal data within 30 days, except where retention is required by law (e.g., tax or accounting obligations under Austrian law).
5. Your Rights (DSGVO Art 15–21)
Under the GDPR/DSGVO, you have the right to:
- Access your personal data (Art 15)
- Rectify inaccurate data (Art 16)
- Erase your data / “right to be forgotten” (Art 17)
- Restrict processing (Art 18)
- Data portability (Art 20)
- Object to processing based on legitimate interest (Art 21)
- Withdraw consent at any time without affecting lawfulness of prior processing
To exercise any of these rights, contact us at office@tagz-social.com.
6. Right to Complain
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Austrian Data Protection Authority:
Datenschutzbehörde
Barichgasse 40-42
1030 Vienna, Austria
dsb@dsb.gv.at
https://www.dsb.gv.at
7. Contact Import
If you choose to import contacts, phone numbers are hashed on your device before any server matching. We do not store raw contact names or phone numbers on our servers, and account deletion removes TAGZ phone-hash records associated with your account.
8. Children’s Privacy
TAGZ account creation and social features are not intended for users under 14 years of age (in accordance with Austrian DSGVO provisions). Every authentication or gated social entry point presents a 14+ acknowledgment and a “Not now” exit; signed-out public browsing remains available without the acknowledgment. We do not knowingly collect account information from users under 14. If we learn we have collected such information, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the app or email.
10. Contact Us
For privacy questions or to exercise your rights, contact us at: office@tagz-social.com