← Back to Home
Privacy Policy
Effective Date: June 27, 2026
Last Updated: June 27, 2026
1. Introduction
Stammtisch ("we," "our," or "us") provides mobile apps and website services that help people create recurring social groups, invite members, suggest dates and places, vote, RSVP, receive reminders, and keep a history of gatherings (the "Service").
This Privacy Policy explains what information we collect, how we use it, when we share it, and how you can contact us about privacy requests. We design the Service to support privacy rights under laws such as the GDPR, UK GDPR, CCPA/CPRA, and other applicable privacy laws where they apply.
2. Information We Collect
2.1 Information You Provide
- Account information: Email address, display name, password credentials handled through Firebase Authentication, email verification status, account status, and login metadata.
- Profile and preference information: Language, hometown or location fields, notification preferences, profile photos, and app settings.
- Stammtisch content: Group names, descriptions, visibility settings, photos, member lists, pending join requests, invitations, proposed dates, proposed locations, votes, RSVPs, comments or messages where available, and event history.
- Communications: Emails, push notifications, support requests, partner venue submissions, contact form messages, and similar communications you send or receive through the Service.
- Venue and website form information: Venue name, contact person, email, phone number, address, website, availability, special offers, and other details submitted through the website.
2.2 Information Collected Automatically
- Device and app information: Device type, operating system, app version, language, diagnostics, crash or error information, and security/app integrity signals.
- Usage and analytics data: Website visits, app interactions, feature usage, referral pages, approximate location derived from network information, and aggregated performance data.
- Log data: IP address, timestamps, request metadata, authentication events, Cloud Functions logs, Firestore/Storage access logs, and security diagnostics.
- Push notification data: Device push tokens, delivery status, and notification read/archived state.
2.3 Third-Party and Integrated Services
- Firebase/Google Cloud: Authentication, Firestore database, Cloud Storage, Cloud Functions, Firebase App Check, Firebase Cloud Messaging, hosting, logging, and related infrastructure.
- Google Maps and Places: Location search, place autocomplete, maps, and place details used to suggest or display meeting places.
- Email providers: Transactional and operational email delivery, including email verification, welcome emails, reminders, admin alerts, and support messages.
- Formspree: Website contact and partner venue form submissions.
- Google Analytics: Website analytics used to understand traffic and improve the website.
- Apple App Store and Google Play: App distribution, installation, and store-level account/payment information handled by the respective store providers.
- Payment providers: If paid plans become available, payment information is processed by the app stores or payment processors. We do not intend to store full payment card details.
3. How We Use Information
- Provide, operate, secure, and improve the Service.
- Create accounts, verify email addresses, authenticate users, and prevent abuse.
- Create and manage Stammtisch groups, invitations, join requests, votes, RSVPs, reminders, photos, and event history.
- Send transactional emails, push notifications, RSVP reminders, voting reminders, invite messages, service updates, and support responses.
- Provide map and place autocomplete functionality.
- Analyze aggregate usage and diagnose bugs, reliability issues, and security events.
- Enforce our Terms, investigate misuse, and comply with legal obligations.
- Send marketing or product updates only where permitted by law and your preferences.
4. Legal Bases for Processing
Where GDPR, UK GDPR, or similar laws apply, we rely on the following legal bases:
- Contract: To provide the Service you request, including account, group, invite, vote, RSVP, and notification features.
- Legitimate interests: To secure, debug, improve, and operate the Service, prevent fraud or abuse, and understand aggregate usage.
- Consent: For optional marketing communications, certain analytics/cookie uses where required, and optional device permissions.
- Legal obligation: To comply with law, legal process, tax/accounting obligations, and safety/security requirements.
5. Sharing and Disclosure
- Within your Stammtisch groups: Group members may see names, profile details, proposals, votes, RSVPs, photos, comments, and event information needed to coordinate the group.
- With service providers: We share information with vendors that host, secure, analyze, deliver, or support the Service, including Firebase/Google Cloud, Google Maps/Places, email providers, Formspree, analytics providers, and app stores.
- With venues or partners: If you submit a venue form or intentionally share venue-related details, we may use that information to evaluate or coordinate the venue program.
- For legal and safety reasons: We may disclose information when required by law, to protect rights and safety, to investigate abuse, or to enforce our Terms.
- Business transfers: Information may be transferred as part of a merger, acquisition, financing, or sale of assets.
5.1 We Do Not Sell Personal Information
We do not sell personal information. We also do not share personal information for cross-context behavioral advertising as those terms are commonly used under California privacy law. If this changes, we will update this policy and provide required choices.
6. Cookies, Analytics, and Tracking
The website uses Google Analytics and similar technologies to understand traffic and improve the website. Your browser or device settings may let you limit cookies, reset advertising identifiers, or use privacy controls. If required by local law, we will request consent before using non-essential analytics cookies.
7. Data Retention and Deletion
- Account data: Kept while your account is active. When you delete your profile, we delete or anonymize the account record and authentication identity where technically available.
- Group membership data: Removed or anonymized when your account is deleted, subject to preserving group integrity for other members.
- Event history and statistics: Past proposals, votes, RSVP summaries, and event history may be retained in archived or aggregated form so groups can keep their history and statistics without exposing an active deleted profile.
- Photos and user content: Removed when you delete the relevant content or account where technically possible, unless retained for legal, safety, backup, or abuse-prevention reasons.
- Notifications and email records: Retained for operational, delivery, audit, and support purposes, then deleted or anonymized according to our retention practices.
- Logs and backups: Security, diagnostic, and backup data may persist for a limited period before routine deletion.
8. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for certain processing of your personal information. California residents may also have the right to know categories of information collected, disclosed, or shared, and to be free from discrimination for exercising privacy rights.
To exercise privacy rights, contact us at drjmudev@gmail.com. We may need to verify your identity before completing a request.
9. Security
We use reasonable technical and organizational safeguards, including Firebase Authentication, access controls, Firebase App Check, Firestore and Storage rules, HTTPS/TLS, role-based administration, secret management, and security logging. No internet service is perfectly secure, so we cannot guarantee absolute security.
10. International Transfers
Your information may be processed in the United States and other countries where we or our service providers operate. Where required, we rely on appropriate safeguards such as contractual commitments, standard contractual clauses, and provider data processing terms.
11. Children's Privacy
The Service is not intended for children under 16 or the minimum age required in your jurisdiction. We do not knowingly collect personal information from children. If you believe a child has provided information, contact us so we can take appropriate action.
12. User Content, Photos, and Public Visibility
Some content may be visible to other users depending on group visibility and membership. Public groups may expose group names, descriptions, locations, photos, and join/request information more broadly than private groups. Please avoid sharing private addresses, sensitive personal details, or photos you do not have permission to upload.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the date above and may notify users through the website, app, email, or in-app notices when changes are material.
14. Contact
For privacy questions or requests, contact us:
- Privacy: drjmudev@gmail.com
- Support: drjmudev@gmail.com
- Website: https://stammtisch.pro
If GDPR or similar laws apply, Stammtisch is the controller of personal information processed for the Service unless otherwise stated. You may also have the right to lodge a complaint with your local data protection authority.