Legal

Privacy Policy

Effective: May 13, 2026 Last updated: May 13, 2026
Crowdstirr Crowdstirr Social Beacon Crowdstirr Business
Crowdstirr is built for adults (18+). We collect the minimum data necessary to run the platform, we encrypt your messages, and we never sell your personal information to third parties.

Who We Are

CrowdStirr LLC ("Crowdstirr", "we", "us", or "our") operates the Crowdstirr, Crowdstirr Social Beacon, and Crowdstirr Business mobile applications (collectively, the "Apps") and the supporting API at app-prod1.crowdstirr.com.

Contact: info@crowdstirr.com

Information We Collect

2.1 Information you provide directly

  • Account details — display name, username, date of birth, profile photo, account type (standard / business / influencer).
  • Contact information — email address and/or phone number used to sign in.
  • Interests — up to 12 interest categories you select during onboarding (e.g. Music, Sports, Technology).
  • Business information — business name, category, and description (Crowdstirr Business only).
  • Payment information — processed securely by Stripe. We store only a tokenised reference (last 4 digits, card brand, expiry). We never see or store your full card number.
  • Content you post — event listings, photos, poll questions, and chat messages.

2.2 Information collected automatically

  • Precise location — used by certain location-based features when you have actively enabled them and granted permission. Where location is shared with others through the Apps, we apply additional processing to limit precision before transmission.
  • Device identifiers — push notification tokens, device type, and operating system version.
  • Usage analytics — aggregated, anonymized in-app events (such as screens viewed and features used), collected via analytics infrastructure we operate. We do not transmit this data to third-party analytics providers.
  • Crash and performance data — collected via standard mobile crash-reporting tooling.

2.3 Information from third-party sign-in

  • Sign in with Apple — we receive your Apple ID, name (if shared), and relay email. We process Apple's server-to-server notifications (email forwarding changes, consent revocation, account deletion) at the endpoint registered with Apple.
  • Sign in with Google — we receive your Google account name, email, and profile photo URL.

How We Use Your Information

We use the information described in Section 2 for the purposes listed below. Where required by applicable law, we identify the legal basis for each purpose.

PurposeCategories of data usedLegal basis
Providing the service and managing your accountIdentifiers, contact information, profile dataContract
Operating core in-app features and personalizing your experienceActivity, preferences, and (where you have granted permission) locationContract / Consent
Communications and notificationsContact information, device tokens, notification preferencesContract / Consent
Processing payments and transactionsTokenized payment data, billing detailsContract
Maintaining safety, integrity, and security of the platformAccount activity, abuse signals, report dataLegitimate interest
Showing relevant advertising on free tiers, where applicableAdvertising identifiers, general preferencesConsent (ATT on iOS)
Understanding how the apps are used and improving themAggregated, anonymized usage eventsLegitimate interest
Complying with legal obligationsAs required by applicable lawLegal obligation

We do not use your information for any purpose materially different from those described above without first notifying you and, where required, obtaining your consent.

Chat Messages and Encryption

All chat messages — both direct messages and group chats — are protected with industry-standard authenticated encryption applied before they leave your device. Messages are decrypted only on the recipient's device. Crowdstirr servers store only the encrypted ciphertext and cannot read your message content.

Messages are retained for a limited period after delivery in accordance with our retention policy (see Section 9), and you may delete individual messages or entire conversations at any time.

On-Device Personalization

Some features in the Apps use on-device processing to personalize your experience. On-device processing means the analysis runs entirely on your device — your message content, the specific words you write, and any personal identifiers do not leave your device.

Where an on-device feature benefits from limited continuity across sessions or devices (for example, so your preferences survive a phone change), only aggregated, non-identifying summaries may be synced. We do not sync, store, or have access to the underlying content these features process.

You can disable on-device personalization features at any time in Settings ? Privacy.

Location Data

Certain in-app features may request precise location with your permission. When you enable a location-based feature, location data is:

  • Used in real time to support that feature while it is active.
  • Processed to reduce precision before being shared with other users through the Apps — your exact coordinates are not exposed to other users.
  • Retained only as long as needed to provide the feature, except where it forms part of a record you have intentionally created (for example, a venue check-in stored with that event).
  • Never sold, and never shared with advertisers in precise form.

You can revoke location permission at any time in your device settings. This will disable location-dependent features.

Advertising

Some tiers of the Apps may display native advertising provided through a third-party advertising network. Where advertising is shown, it may use device advertising identifiers, general preferences, and broad location signals to select what to display.

On iOS, we request App Tracking Transparency (ATT) permission before any personalized advertising. If you decline, you will receive non-personalized ads. Premium subscribers do not see ads.

Where advertising is provided through a third party, that provider's own privacy policy will also apply to data processed by their service.

Data Sharing

We do not sell your personal information. We share data only with:

RecipientPurposeData shared
StripePayment processingPayment card data (tokenised), billing details
Google FirebaseAuthentication, database, push notifications, storageAccount data, FCM tokens
Advertising networkNative advertising on supported tiersDevice advertising ID, general location, interests
Google Maps PlatformMap display and geocodingLocation data
AppleSign in with Apple authentication notificationsApple user ID, relay email
Law enforcement / legal processCompliance with valid legal requestsAs required by law

Data Retention

  • Account data — retained while your account is active. Deleted within 30 days of account deletion request.
  • Chat messages — retained for a defined period after delivery in accordance with our internal retention schedule. Permanently deleted on account deletion.
  • Location data — retained only as long as needed to provide the feature in use; location that you intentionally associate with a record (such as a venue check-in) is retained with that record.
  • Payment records — retained for 7 years for tax and legal compliance (financial records only; card data held by Stripe).
  • Analytics data — anonymised; retained for up to 2 years.

Your Rights and Choices

Depending on your location, you may have the following rights:

  • Access — request a copy of the personal data we hold about you.
  • Correction — update inaccurate or incomplete data (most fields are editable in-app).
  • Deletion — request deletion of your account and associated personal data. Submit a request in-app via Settings ? Account ? Delete Account or email info@crowdstirr.com. Deletion is completed within 30 days.
  • Portability — request an export of your data in a machine-readable format.
  • Opt-out of personalised ads — decline ATT on iOS, or toggle off in Settings ? Privacy ? Personalised Ads.
  • Push notification opt-out — manage in Settings ? Notifications or your device settings.
  • Location opt-out — revoke location permission in your device settings.

To exercise any right, contact us at info@crowdstirr.com. We will respond within 30 days.

Children's Privacy

Crowdstirr is intended for users 18 years of age and older. We collect date of birth during registration and do not knowingly permit accounts for users under 18. If we become aware that a user under 18 has registered, we will delete their account and associated data promptly. If you believe a minor has created an account, please contact us at info@crowdstirr.com.

Security

We use industry-standard security measures, including:

  • Modern transport-layer encryption for all data in transit.
  • Industry-standard authenticated encryption for chat messages, applied end-to-end on the message body.
  • Modern API abuse protection to prevent access from unofficial clients.
  • Authentication hardening against common credential and timing-based attacks.
  • Internal access controls limiting employee access to personal data on a need-to-know basis.

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at info@crowdstirr.com.

International Data Transfers

Our servers are located in the United States and the European Union. If you access the Apps from outside these regions, your information may be transferred to and processed in these jurisdictions. We apply appropriate safeguards (including Standard Contractual Clauses where required) for transfers of personal data from the EEA or UK.

California Privacy Rights (CCPA)

California residents have the right to know what personal information we collect, to request deletion, and to opt out of the "sale" of personal information. We do not sell personal information. To exercise your rights, contact info@crowdstirr.com.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via a push notification and/or an in-app prompt requiring you to review and accept the updated policy before continuing to use the Apps. The "Last updated" date at the top of this page reflects the most recent revision.

Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact:

CrowdStirr LLC
Privacy enquiries: info@crowdstirr.com
Security issues: info@crowdstirr.com
General: info@crowdstirr.com