Bachat’Up

Legal

Privacy policy

Version 2026-09   Effective 21 September 2026 · Applies to the Bachat’Up mobile app (version 1.0) and to this website.

The short version

Bachat’Up is a catalogue of bachata events. You can browse all of it without an account. If you make one, we keep the few things the app needs to work: who you are, what you said you were going to, and where to send your reminders. Everything lives in the EU. Nothing is sold, nothing is shared with advertisers, and there is no tracking of any kind. You can export it all, or delete it all, from inside the app.

1. Who is responsible

Bachat’Up (“we”) is the data controller for the personal data described here. You can reach us about anything in this policy, including any request about your rights, at privacy@bachatup.com.

For the event listings themselves, the organizer who submits an event is the controller of that event’s data and we act as processor for it.

2. What we collect, why, and on what basis

This is the whole inventory for version 1.0. It matches the privacy manifest shipped inside the app binary.

Account

email address, the sign-in identity you used (Sign in with Apple, or email and password), display name, account creation date

Why
To create and run your account.
Legal basis
Contract, Art. 6(1)(b)
Kept for
Until you delete your account.

Profile

dance role, style preferences, the city and country you declare, optional bio, optional profile photo, time zone

Why
To tailor the catalogue to where you are and what you dance, and to show your name and photo on the parts of the app that are shared.
Legal basis
Contract, Art. 6(1)(b)
Kept for
Until you delete your account.

RSVPs

the event, whether you said Interested or Going, and when

Why
To build your own list and to send the reminder you asked for; organizers see attendance counts.
Legal basis
Contract, Art. 6(1)(b), and legitimate interest for organizer counts, Art. 6(1)(f)
Kept for
2 years after the event date, then deleted.

Artist follows

the artist and when you followed

Why
To surface events featuring artists you follow.
Legal basis
Legitimate interest, Art. 6(1)(f)
Kept for
Until you unfollow or delete your account.

Event views and ticket taps

which event, when, and which part of the app you came from

Why
First-party measurement in our own database: organizers get counts for their events, and popular events can be surfaced. This is not an advertising or tracking product and no third party receives it.
Legal basis
Legitimate interest, Art. 6(1)(f)
Kept for
Views are deleted after 90 days. Ticket taps are unlinked from your account after 90 days; only anonymous daily totals remain.

Approximate location

a coordinate rounded to about 1 km

Why
Only to answer “what is near me” and to sort by distance, at the moment you tap it.
Legal basis
Consent, Art. 6(1)(a)
Kept for
Never stored. It is held in the app’s memory for the session and is gone when the app closes.

Notifications

your notification preferences and quiet hours, plus one row per device holding the push token, the platform, a randomly generated install identifier, the device name and the app version

Why
To deliver the reminders and alerts you switched on, and to stop sending to devices you signed out of.
Legal basis
Contract, Art. 6(1)(b), after the operating system permission you grant
Kept for
Until you sign out, turn notifications off, or delete your account.

Consent records

which consent, your decision, the policy version and the timestamp

Why
To prove that a choice was offered and respected, and to ask again when this policy changes materially.
Legal basis
Legal obligation, Art. 6(1)(c)
Kept for
Until you delete your account.

Things you write

event corrections, reports, organizer submissions and verification links, your bio

Why
To fix and moderate the catalogue, and to review organizer applications.
Legal basis
Contract, Art. 6(1)(b)
Kept for
Corrections: 1 year after they are resolved. Organizer verification: while you hold the role, plus one year.

Interest in features that are not live yet

which upcoming section you tapped, and when

Why
To notify you when that part of the app opens.
Legal basis
Consent, Art. 6(1)(a) — the tap itself
Kept for
Until 90 days after that feature launches.

Age

Bachat’Up is for people aged 16 and over. At sign-up you confirm you are 16 or older. We record only that the confirmation happened — no date of birth is stored.

Your profile photo

If you set one, it is uploaded to our EU storage bucket and served from a public image URL, the same way any avatar in an app with shared surfaces is. Do not upload anything you would not want visible to another user of the app.

3. What we do not do

4. Where your data lives, and who else touches it

Everything is stored in the European Union: our database, authentication and file storage run on Supabase in the eu-central-1 region (Frankfurt, Germany), which acts as our processor.

Two things necessarily leave that boundary, and only these:

Tapping a ticket link opens the organizer’s or ticket seller’s own website, which has its own privacy policy and is outside our control.

5. What other people can see

Organizers of an event can see attendance counts, and the public profile fields (display name, photo, dance role, city) of attendees who have not hidden their RSVPs. They never see your email address. Settings → Privacy has a switch, Hide my RSVPs from organizers, that reduces you to an anonymous count.

6. Your rights

Under the GDPR you have the rights below. The first two are built into the app and work immediately — you do not have to email anyone.

If you would rather write to us than use the app, email privacy@bachatup.com and we will answer within one month.

7. How long we keep things

The retention column in section 2 is not aspirational: it is enforced by scheduled jobs that run every day against the database. They delete event views older than 90 days, strip the account link from ticket taps older than 90 days, delete RSVPs 2 years after the event happened, remove resolved corrections after a year, and hard-delete accounts that have been in the 30-day deletion grace period.

8. Security

Every table in the database is protected by row-level security, so one account cannot read another’s private rows. Your session is stored encrypted on the device. Private files, such as a data export, are only reachable through short-lived signed links. Administrative actions are logged.

9. Changes to this policy

This policy is versioned (the version is shown at the top of this page and inside the app, in Settings → Privacy). If we change it materially, the app asks you to read the change and confirm your choices again before you carry on using it.

10. Contact

Privacy questions and rights requests: privacy@bachatup.com.