1Introduction
SPOTR ("we", "us", or "our") is a location-based community app that lets people pin and discover real-time events, hazards, and offers near them. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices you have.
By using SPOTR you agree to the practices described in this policy. If you disagree, please do not use the app.
2Information We Collect
2.1 Account Information (from Google Sign-In)
When you sign in with Google, we receive:
- Your Google account email address
- Your display name
- Your Google profile photo URL
- A unique Google account identifier
We receive only the information Google provides through its standard OAuth 2.0 flow. We do not receive your Google password or any information beyond what you authorise at sign-in.
2.2 Profile Information (provided by you)
During registration you provide:
| Field | Required? | Visibility |
|---|---|---|
| Username | Required | Publicly visible |
| Full name | Required | Publicly visible |
| Gender | Optional | Displayed on your profile |
| Profile picture | Optional | Publicly visible; stored in our cloud storage |
2.3 Precise Location
SPOTR uses your device's GPS to show you spots happening nearby. We access location only while the app is open (foreground access). We never access your location in the background.
Your location is used to:
- Query and display nearby spots on the map
- Tag the exact GPS coordinates of spots you create (these coordinates are stored and publicly visible to other users)
We do not build a history of where you have been. Location is used in real time for map queries and is stored permanently only when you voluntarily pin a spot.
2.4 User-Generated Content (Spots)
When you create a spot you provide:
- Title and description
- Category (Event, Hazard, or Offer)
- A photo (required)
- Duration (how long the spot stays live)
We automatically attach your current GPS coordinates and the creation timestamp. All spot content — including the photo and exact location — is publicly visible to all SPOTR users.
2.5 App Activity
| Activity | What we store | Purpose |
|---|---|---|
| Likes | Which spots you liked (linked to your user ID) | Show engagement counts on spots |
| Views | Which spots you viewed (linked to your user ID) | Show engagement counts on spots |
This data is not currently displayed publicly per-user and is not used for targeted advertising.
2.6 Device and Technical Information
We do not use analytics SDKs, crash-reporting tools, or advertising identifiers. We do not collect your device ID, IP address logs, or browsing history.
3How We Use Your Information
| Purpose | Data used |
|---|---|
| Authenticating your account | Google OAuth token, email, user ID |
| Displaying nearby spots on the map | Your real-time GPS location |
| Showing your profile to other users | Username, name, gender, profile picture |
| Publishing spots you create | Title, description, category, photo, GPS, timestamp |
| Showing like and view counts | Like and view records tied to your user ID |
| Improving the app | Aggregated, non-identifiable usage patterns |
4Information Sharing and Disclosure
4.1 What Other Users Can See
| Data | Visible to other users? |
|---|---|
| Username | Yes – on all your spots and your profile |
| Full name | Yes – on your profile |
| Profile picture | Yes – on your profile and your spots |
| Gender | Yes – displayed on your profile |
| Spots you created (photo + location + text) | Yes – publicly visible on the map |
| Email address | No – never shown to other users |
| Which spots you liked or viewed | No – only aggregate counts are shown |
4.2 Third-Party Service Providers
We share data with the following sub-processors to operate the app:
| Provider | Role | Data shared | Privacy policy |
|---|---|---|---|
| Supabase | Database, authentication backend, and file storage | All user data, location data, content, and activity logs | supabase.com/privacy |
| Authentication (Sign in with Google) | OAuth handshake; we receive name, email, profile photo | policies.google.com/privacy | |
| Mapbox | Map tile rendering | Map tile requests (your approximate viewport location is implicit in which tiles are loaded) | mapbox.com/legal/privacy |
We do not sell, rent, or trade your personal information to any other third parties for commercial purposes.
4.3 Legal Requirements
We may disclose your information if required by law, court order, or governmental authority, or to protect the safety and rights of users or the public.
5Data Retention
| Data type | Retention period |
|---|---|
| Account and profile data | Until you delete your account |
| Spots | Until you delete the spot or your account. The spot's listed duration affects its visual display, not when it is deleted from our servers. |
| Likes and views | Until you delete your account |
| Authentication records | Deleted when your account is deleted |
When you delete your account we permanently and irreversibly remove your profile, all your spots (including their photos), and your activity records. Deletion is processed within 30 days.
6Your Rights and Choices
6.1 Access and Correction
You can view and edit your profile (username, name, gender, profile picture) at any time in the app under your profile page → Edit.
6.2 Account Deletion
You can permanently delete your SPOTR account from within the app: Profile → Settings → Delete Account. This deletes all your personal data, spots, photos, and activity from our systems.
6.3 Location
You can revoke location permission at any time in your device settings. Without location access the core map functionality of SPOTR will not work.
6.4 Camera and Photo Library
You can revoke camera and photo library permissions at any time in your device settings. You will not be able to create new spots without camera access.
6.5 GDPR Rights (EEA / UK users)
If you are in the European Economic Area or the United Kingdom, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request erasure of your data ("right to be forgotten") – use the in-app Delete Account feature or email us
- Restrict or object to processing
- Data portability
- Lodge a complaint with your local data protection authority
6.6 CCPA Rights (California users)
California residents have the right to know what personal information we collect and how it is used, to request deletion, and to opt out of the sale of personal information. We do not sell personal information.
7Children's Privacy
SPOTR is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, please contact us at 1.suyashk@gmail.com and we will promptly delete the account and all associated data.
8Data Security
We implement industry-standard security measures including:
- All data transmitted between the app and our servers is encrypted in transit using TLS
- Authentication is handled by Supabase Auth with secure session token storage
- Access to the database is controlled by row-level security policies
- Photos are stored in access-controlled Supabase Storage
No method of transmission over the Internet is 100% secure. We cannot guarantee absolute security, but we take reasonable measures to protect your information.
9International Data Transfers
Our service provider Supabase may store and process your data in data centres located outside your country of residence. By using SPOTR you consent to the transfer of your data to these locations. Where such transfers occur we rely on appropriate safeguards (such as standard contractual clauses) as required by applicable law.
10Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by updating the effective date at the top of this page and, where appropriate, by in-app notification. Your continued use of SPOTR after any change constitutes your acceptance of the updated policy.
11Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
| 1.suyashk@gmail.com | |
| Website | spotr.goastral.in |
We aim to respond to all privacy-related enquiries within 30 days.