Privacy policy
Last updated: June 2026
What we collect, and why
- Username and password. So you can log in. The password is stored hashed (bcrypt). we never see or store it in plain text.
- Location: only if the entry check is switched on. When it is, signup uses one location fix to check you're within 50 km of the festival, and we store just that single position and its timestamp and never a trail. With the check off (the current default), signup collects no location at all. Meetup pins you choose to drop in a chat are stored as part of that conversation.
- Contact handles (WhatsApp / Telegram / Instagram) if you choose to add them. They are only ever shown to someone when you yourself tap "share" inside an accepted trade. They are never public, never searchable, and never given out in bulk.
- Your listings, offers, chats and ratings. That's the app working.
- Reports. If you report someone, the report is stored with your account so the admin can make sense of it. The reported person is never told who reported them.
What we don't do
- No analytics, no ad tracking, no cookies beyond the login session.
- No selling or sharing data with anyone.
- No payment data. The app never touches money.
How long we keep it
Accounts, listings, chats, reports: all of it is permanently deleted after the festival, when we take the service down. You can also delete your account yourself at any time from your profile page, which wipes your data immediately.
Who runs this
A single private person, as a hobby project, hosted in the EU. Questions or data requests: use the contact handle posted at the info desk, or just delete your account from the profile page.
